Japanese-style illustration of a young black-cat hacker testing a system on a MacBook Pro with an official Siam Thanat Hack sticker

Human-Led AI-Augmented

Professional penetration testing with the power of STH experts and AI

Pentest and penetration testing services for Web, Mobile, API, and Network With verifiable evidence and actionable remediation guidance

Siam Thanat Hack certifications

CREST Pathway Plus
Request a pentest quote Explore our services
Scroll to explore

OFFENSIVE SECURITY / 01

Our services

Find exploitable vulnerabilities with evidence and practical remediation.

01 / WEB APPLICATION

Go deeper than the OWASP Top 10

Test web applications for exploitable vulnerabilities, including business logic flaws scanners miss.

Coverage

  • OWASP Top 10 and OWASP ASVS
  • Authentication, sessions, and authorization
  • IDOR, injection, SSRF, and business logic

What you receive

Executive and technical reports with evidence, reproduction steps, impact, remediation, and scoped retesting.

02 / MOBILE APPLICATION

See the complete mobile app and connected backend

Test both the app and backend/API against the OWASP Mobile Top 10 to find exploitable vulnerabilities.

Coverage

  • On-device storage and encryption
  • TLS, certificate pinning, and sessions/tokens
  • Reverse engineering, tampering, and business logic

What you receive

Reporting and recommendations for the app and backend, a results briefing, and retesting within the agreed scope.

03 / API PENETRATION TESTING

Test every endpoint and connect the attack chain

Find authentication, authorization, rate-limiting, and data-exposure vulnerabilities in REST and GraphQL APIs.

Coverage

  • REST, GraphQL, and tokens/sessions
  • BOLA/IDOR, rate limits, and abuse
  • Mass assignment, data exposure, and business logic

What you receive

Endpoint-level reporting with evidence, reproduction steps, impact, and developer-ready recommendations.

04 / NETWORK

Validate attack paths from the perimeter to critical systems

Test external and internal networks within the mutually agreed scope and Rules of Engagement.

Coverage

  • Internet-facing services and VPN gateways
  • Internal networks, lateral movement, and Active Directory
  • Misconfiguration, privilege escalation, and segmentation

What you receive

Executive and technical reporting with network-segmentation evidence and scoped retesting.

05 / SECURE CODE REVIEW

Inspect logic beyond the reach of black-box tests and scanners

Manually analyze source code for vulnerabilities and logic flaws with practical remediation.

Coverage

  • Code-level authentication and authorization
  • Input validation, injection, and deserialization
  • Secrets, encryption, dependencies, and framework configuration

What you receive

Reporting with file/line locations, impact, fixes, and architectural guidance where needed.

06 / VULNERABILITY RESEARCH

Go deep into binaries, protocols, and exploitability

Research binaries, protocols, or codebases that require more than conventional checklist testing.

Coverage

  • Analyze specialized binaries, protocols, or codebases
  • Fuzzing, reverse engineering, and proof of concept
  • Assess impact and produce an advisory

What you receive

An advisory with proof of concept, risk prioritization, impact, and mitigation guidance.

Humans define scope and validate every finding. Within the authorized scope, AI runs automated active testing to increase speed, coverage, and efficiency against techniques real attackers may use.

ASSESSMENT GUIDE

VA Scan, Pentest and Red Team: which assessment do you need?

Each assessment answers a different question. Choose according to the objective, scope, and evidence you need; they are not automatic substitutes for one another.

Diagram comparing VA Scan, Pentest, and Red Team with an expert cat and AI robot for each assessment type

01 / VA SCAN

VA Scan / Vulnerability Assessment

Broadly discover and prioritize vulnerabilities. Scanner-only VA does not replace a Pentest.

Choose it when: You need an initial assessment of a large network environment, broad visibility of many vulnerabilities, and a plan for deeper validation.

02 / PENTEST

Pentest / Penetration Testing

Experts use manual testing to validate exploitability and impact within the agreed scope.

Choose it when: You need evidence that vulnerabilities are exploitable and remediation guidance for critical Web and Mobile applications.

03 / RED TEAM

Red Team

Simulate objective- and threat-led scenarios under explicit Scope and Rules of Engagement to assess prevention, detection, and response objectives.

Choose it when: You already run VA and Pentest regularly and need to test how people, processes, and technology respond to a defined scenario.

เลื่อนตารางในแนวนอนเพื่อดูทุกคอลัมน์ Scroll horizontally to view every column

Assessment dimension VA Scan Pentest Red Team
Coverage
* Targets the stated objective, such as taking over a Domain Controller or implanting a backdoor while evading SOC detection, rather than seeking the greatest possible number of vulnerabilities.
Exploit proof
* Excludes vulnerabilities that could affect business continuity.
Real-world simulation
* Testing focuses on non-production systems to reduce impact.
* Focuses on testing detection and response processes.

Read the article: How Pentest differs from VA

ABOUT STH / 02

About

STH is a Thai white-hat team in Bangkok, combining deep expertise, operational discipline, and auditable communication.

The company was incorporated on 11 December 2018 and operates from Bangkok.

01

Roots in knowledge sharing

STH grew from knowledge sharing. Former operators of the Facebook page Longhackz then expanded into CTF competitions, challenge creation, vulnerability research, and high-difficulty technical advisory work.

02

Experience with critical systems

Our specialists have worked on critical systems for banks, payment gateways, and leading organizations. We work strictly within an authorized scope and Rules of Engagement. We do not perform unauthorized access, account hacking, or account recovery.

03

Human-Led, AI-Augmented

Humans define scope and validate every finding. Within the authorized scope, AI runs automated active testing to increase speed, coverage, and efficiency against techniques real attackers may use.

Within the authorized scope, we use AI for reconnaissance and automated attack testing to explore the attack surface and test hypotheses faster. Specialists define scope, control testing, reproduce findings, assess impact, and approve the final report.

Professional certifications represented across the team

HUMAN-LED × AI-AUGMENTED / 03

We test your systems from start to finish

Experts define scope, control testing, and validate results while AI runs automated active testing within scope to increase speed and coverage.

Human pentester, target system on phone and computer, and robotic-cat AI agent

Human owns the decision

Experts lead every step from scope to sign-off

  • Define scope, Rules of Engagement, and the test window
  • Model threats and find abuse cases scanners cannot see
  • Manually exploit and assemble attack chains
  • Assess impact, risk, and remediation before reporting

Evidence from the real surface

Test real system behavior, not just a checklist

  • Web, mobile, API, and network testing within the agreed scope
  • Assess access control, sessions, data exposure, and business logic
  • Capture reproducible evidence with clear impact explanations
  • Deliver remediation guidance development teams can apply

AI tests actively; humans retain authority

AI runs automated active testing; humans validate every finding

  • Perform reconnaissance and automated attack testing within the authorized scope
  • Build an evidence index and check coverage consistency
  • Assist with report drafting while every final report receives human review
  • An AI hypothesis never becomes a finding until a human reproduces it

DELIVERY FLOW / 04

Our delivery process

Every phase has a clear owner, evidence, and decision gate.

Phase 01 details

Plan

Turn business objectives into a clear, safe, and authorized testing scope before work begins.

Owner Engagement Lead Estimated duration 1-2 business days

What we do

  • Confirm in-scope and out-of-scope systems, domains, IP addresses, APIs, and applications
  • Prepare test accounts, access rights, MFA, and test data
  • Define the test window, Rules of Engagement, and stop conditions
  • Define communication channels and escalation procedures for critical events

Deliverables

  • Approved Scope & Rules of Engagement
  • Asset and Account Matrix
  • Test Schedule
  • Communication and Escalation Plan

Evidence

  • Testing authorization letter
  • System and endpoint inventory
  • Access Readiness Checklist
  • Contacts and approvers

Framework Mapping

Engagement GovernanceOWASP WSTG v4.2Authorized Testing

Decision Gate Begin testing only after scope, access, the test window, and ROE are fully confirmed.

View scope and ROE

Phase 02 details

Analyze

Build a threat model and attack-surface map to prioritize likely, high-impact attack paths.

Owner Lead Pentester / Security Analyst Estimated duration 1-3 business days

What we do

  • Analyze architecture, trust boundaries, and data flows
  • Build a threat model and abuse cases
  • Map the attack surface and exposed technologies
  • Analyze roles, privileges, and paths to sensitive data
  • Prioritize test scenarios by risk and impact

Deliverables

  • Attack Surface Map
  • Threat Model and Abuse Cases
  • Prioritized Test Scenarios
  • Initial Attack Hypotheses

Evidence

  • Endpoint and service inventory
  • Role and Privilege Matrix
  • Data flows and trust boundaries
  • Reconnaissance Artifacts

Framework Mapping

MITRE ATT&CK v19.1ReconnaissanceResource development - when authorized and in scopeOWASP WSTG: Information Gathering

Phase 03 details

Test

Perform authorized manual offensive testing to validate vulnerabilities and connect them into attack chains.

Owner Technical Lead / Pentest Team Estimated duration 5-15 business days

What we do

  • Test authentication, authorization, and session management
  • Analyze business logic and workflow bypasses
  • Validate vulnerabilities through manual exploitation
  • Connect multiple vulnerabilities to assess attack-chain impact
  • Keep testing within the Rules of Engagement

Deliverables

  • Verified Security Findings
  • Proof of Concept
  • Attack Chain Diagram
  • Test Coverage Matrix

Evidence

  • HTTP Requests and Responses
  • Screenshots and Screen Recordings
  • Commands, Logs and Tool Output
  • PoC code and impact evidence

Framework Mapping

OWASP Top 10:2025OWASP WSTG v4.2 Test IDsMITRE ATT&CK v19.1 Tactics & TechniquesOnly tested and validated behavior

Phase 04 details

Validate

Recheck results to remove false positives, define affected scope, and assess risk from proven evidence.

Owner Validation Lead / QA Reviewer Estimated duration 1-3 business days

What we do

  • Reproduce vulnerabilities under controlled conditions
  • Review attack preconditions and constraints
  • Use negative controls to distinguish expected behavior from vulnerabilities
  • Assess impact on confidentiality, integrity, and availability
  • Analyze business impact and real-world exploitability

Deliverables

  • Validated Findings
  • Affected Asset and Scope
  • Impact Analysis
  • Risk Rating and Rationale
  • Remediation Priority

Evidence

  • Reproduction Steps
  • Successful and Failed Test Cases
  • Privilege or data impact
  • Preconditions and Environmental Context

Framework Mapping

OWASP Top 10:2025 CategoryOWASP WSTG Test ReferenceMITRE ATT&CK Technique MappingImpact & Risk Validation

Decision Gate Classify results as Confirmed, Informational, or Rejected with traceable rationale.

View risk rationale

Phase 05 details

Report

Turn test results into prioritized, actionable information for executives and technical teams.

Owner Report Owner / QA Reviewer Estimated duration 3-5 business days

What we do

  • Summarize the overall risk and business impact
  • Document technical details and reproduction steps
  • Show attack paths and relationships between vulnerabilities
  • Recommend immediate and long-term remediation
  • Quality-review and remove unnecessary sensitive data from evidence

Deliverables

  • Executive Report
  • Technical Pentest Report
  • Finding and Evidence Register
  • Attack Chain Visualization
  • Prioritized Remediation Plan

Evidence

  • Sanitized Screenshots
  • Request and Response References
  • PoC and Reproduction Steps
  • Evidence Traceability Index

Framework Mapping

OWASP Top 10:2025 CoverageOWASP WSTG Test CoverageMITRE ATT&CK Attack PathFinding-to-Framework Matrix

Decision Gate Confirm facts, remediation owners, priorities, and items requiring retesting.

View report sample

Phase 06 details

Retest

Retest under the original conditions, check related bypasses or variants, and verify that risk is genuinely reduced.

Owner Original Tester / QA Reviewer Estimated duration 1-3 business days

What we do

  • Repeat the original PoC and test steps
  • Verify the root cause, not only the visible symptom
  • Test related variants and bypass paths
  • Check the fix for impact on existing functionality
  • Compare evidence before and after remediation

Deliverables

  • Retest Report
  • Finding Status Update
  • Closure Evidence
  • Residual Risk Summary
  • Outstanding vulnerability list

Evidence

  • Before and After Requests
  • Updated configuration or application version
  • Retest Screenshots
  • Timestamped Verification Results

Framework Mapping

Original OWASP Reference RetainedOriginal ATT&CK Mapping RetainedFix VerificationClosure Traceability

Decision Gate Confirm each post-retest status with evidence as Closed, Partially Remediated, Open, Unable to Verify, or Risk Accepted.

Timelines are estimates and may change with scope, access, and Rules of Engagement.

Governance & Compliance

Standards & Testing Frameworks

General & National Cybersecurity

Banking & Payment Systems (BOT)

Securities & Digital Assets (SEC) and Insurance (OIC)

VERIFIABLE TRUST / 05

Verifiable standards

Download our certificates and review the principles behind our delivery.

01

Human validation

Every finding is reproduced and manually validated

02

Evidence ready

Evidence, reproduction steps, impact, and remediation are included

03

Responsible AI

AI is an automated testing layer; humans decide the test results

04

Retest closure

Verify remediation and deliver evidence according to the package or scope

START THE CONVERSATION / 06

When you need a pentest,
work with specialists.

Send us your initial system details, testing scope, and preferred timeframe so we can prepare an assessment plan.

PENTEST FAQ / 07

Frequently asked questions about our Pentest services

Answers about scope, pricing, timelines, and regulatory requirements. If you cannot find what you need, talk to the team directly.

What is the difference between a Pentest and a VA Scan, and where should we start?

A VA Scan uses tools to discover vulnerabilities across a wide scope, which suits health-checking many systems and prioritizing risk first. A Pentest is hands-on testing by specialists to prove whether vulnerabilities are actually exploitable, with evidence and remediation guidance. Systems that are business-critical or hold customer data should get a Pentest alongside periodic VA — one does not replace the other.

What expertise and certifications does the testing team hold?

The STH team has hands-on experience testing the applications of leading financial institutions and holds internationally recognized certifications at both the organizational level and the level of the individual specialists who run the tests, and were champions of Thailand Cyber Top Talent 2023. We support your engagement from start to finish — advising at the outset, preparing before testing, communicating vulnerabilities as they are found, and giving careful guidance on closing them.

Is the testing done by real people, or just an automated scanner?

Our work is human-led. Specialists define the scope, do the actual exploitation, and manually validate every finding before it reaches the report. We use AI and automated tools to speed up reconnaissance and widen coverage within the authorized scope, but the work a scanner cannot do — chaining vulnerabilities into a real attack, testing business logic, IDOR, and authentication — stays with our experts. You get proof of real, exploitable impact with false positives already removed, not a ready-made scanner report.

How is Pentest pricing calculated?

Pricing follows the scope: how many systems, the size of each application, the number of functions or API endpoints to test, and the testing model (black-box, gray-box, or white-box). Send us your system details and the team will estimate the effort in man-days and issue a quotation with a clearly defined scope before any work begins.

How long does testing one system take?

It depends on the system's size and complexity. A single application typically takes about one to three weeks including reporting. After your team fixes the findings, we schedule a retest round to confirm the remediation.

What do we receive when testing is complete?

A full report with an executive summary and technical detail. Every finding includes reproduction steps, evidence, a CVSS-based risk rating, and practical remediation guidance. You also get direct access to the testers for questions, and a retest report after fixes.

Do regulators require penetration testing?

Several industries have direct requirements — financial institutions under Bank of Thailand rules, securities and digital asset businesses under the Thai SEC, and card systems under PCI DSS. PDPA and the Cybersecurity Act define risk-based security duties instead. We summarize each authority's requirements, with links to the source documents, at Regulations & standards

What do we need to prepare before testing starts?

Mainly, help us define the scope: the list of systems, URLs or app builds, test accounts for each user role, and the time window that suits you. We then prepare the scope and Rules of Engagement document for written sign-off before work begins.

How safe is our data during the engagement?

All testing happens within a written, authorized scope under a non-disclosure agreement. STH is certified to ISO/IEC 27001:2022 and ISO 9001:2015, which govern how evidence is handled, stored, and delivered throughout the project.

OffSec

OSCP

OffSec Certified Professional

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

การระบุช่องโหว่ การโจมตีระบบ การยกระดับสิทธิ์ Active Directory และการจัดทำรายงานผล

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบที่ลงมือพิสูจน์จริง พร้อมหลักฐานและขั้นตอนที่ทีมเทคนิคทำซ้ำได้

ดูข้อมูล OSCP จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Vulnerability identification, system exploitation, privilege escalation, Active Directory, and professional reporting.

Customer value

Supports practical testing backed by reproducible evidence and technically useful findings.

View official OSCP information

OffSec

OSWE

OffSec Web Expert

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

White-box testing การวิเคราะห์ Source Code การเชื่อมโยงช่องโหว่ และ Custom Exploit Development

คุณค่าต่อลูกค้า

ช่วยค้นหา Server-side และ Logic Flaw ที่ต้องอาศัยการวิเคราะห์เชิงลึกกว่าการสแกนทั่วไป

ดูคู่มือสอบ OSWE จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

White-box testing, source-code analysis, vulnerability chaining, and custom exploit development.

Customer value

Supports deeper discovery of server-side and logic flaws beyond routine scanning.

View the official OSWE exam guide

OffSec

OSEP

OffSec Experienced Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Client-side attacks การหลบหลีก Antivirus และ Application Allow-listing การเชื่อมโยง Attack Path และ Active Directory ขั้นสูง

คุณค่าต่อลูกค้า

ช่วยประเมินว่ามาตรการป้องกันหลายชั้นสามารถหยุดเส้นทางโจมตีที่สมจริงได้เพียงใด

ดูข้อมูล OSEP จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Client-side attacks, antivirus and application allow-listing evasion, attack chaining, and advanced Active Directory.

Customer value

Helps assess how effectively layered defenses resist realistic attack paths.

View official OSEP information

OffSec

OSCE

OffSec Certified Expert

ความน่าเชื่อถือของผู้ออกใบรับรอง

OffSec เป็นผู้ให้บริการหลักสูตร ห้องปฏิบัติการ และการรับรองวิชาชีพด้าน Cybersecurity ที่เน้นการลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Web attacks, Userland Exploit Development, Antivirus Evasion และการโจมตีระบบเครือข่ายหรือ Edge

คุณค่าต่อลูกค้า

เพิ่มมุมมองเชิงลึกสำหรับงานที่ต้องวิเคราะห์ Exploitability และเทคนิคโจมตีระดับต่ำ

ดู OSCE FAQ จาก OffSec

Issuer credibility

OffSec provides hands-on cybersecurity training, labs, and professional certifications.

Demonstrated capability

Web attacks, userland exploit development, antivirus evasion, and network or edge-system attacks.

Customer value

Adds depth to assessments requiring exploitability analysis and low-level attack expertise.

View the official OSCE FAQ

EC-Council

CEH

Certified Ethical Hacker

ความน่าเชื่อถือของผู้ออกใบรับรอง

EC-Council เป็นองค์กรด้านการฝึกอบรมและการรับรองวิชาชีพ Cybersecurity

ความสามารถที่สะท้อน

องค์ความรู้ด้าน Ethical Hacking, Threats, Attack Vectors, Detection, Prevention และ Security Methodology

คุณค่าต่อลูกค้า

สนับสนุนการประเมินที่ครอบคลุมภัยคุกคามหลายรูปแบบภายใต้กรอบจริยธรรมและการอนุญาตที่ชัดเจน

ดูข้อมูลการสอบ CEH จาก EC-Council

Issuer credibility

EC-Council is a cybersecurity training and professional-certification organization.

Demonstrated capability

Ethical-hacking knowledge across threats, attack vectors, detection, prevention, and assessment methodology.

Customer value

Supports broad threat coverage within a clearly authorized and ethical testing process.

View official CEH exam information

CompTIA

CompTIA PenTest+

CompTIA PenTest+

ความน่าเชื่อถือของผู้ออกใบรับรอง

CompTIA พัฒนาผลิตภัณฑ์ฝึกอบรมและการรับรองวิชาชีพ IT แบบไม่ผูกกับผู้ผลิต (vendor-neutral)

ความสามารถที่สะท้อน

Engagement Management, Reconnaissance, Vulnerability Analysis, Exploitation, Post-exploitation, Lateral Movement และ Reporting

คุณค่าต่อลูกค้า

ช่วยให้โครงการมีโครงสร้างตั้งแต่การวางแผนขอบเขตจนถึงคำแนะนำ Remediation ที่นำไปดำเนินการได้

ดูข้อมูล PenTest+ จาก CompTIA

Issuer credibility

CompTIA develops vendor-neutral IT training and certification products.

Demonstrated capability

Engagement management, reconnaissance, vulnerability analysis, exploitation, post-exploitation, lateral movement, and reporting.

Customer value

Supports a structured assessment from scope planning through actionable remediation.

View official PenTest+ information

GIAC

GPEN

GIAC Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

GIAC พัฒนาและบริหารการรับรองวิชาชีพเฉพาะทางด้าน Information Security

ความสามารถที่สะท้อน

การวางแผน Pentest, Reconnaissance, Scanning, Exploitation, Post-exploitation, Pivoting และ Password Attacks

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบโครงสร้างพื้นฐานที่เป็นระบบและเชื่อมโยงผลทางเทคนิคกับเส้นทางโจมตีจริง

ดูข้อมูล GPEN จาก GIAC

Issuer credibility

GIAC develops and administers specialist information-security certifications.

Demonstrated capability

Penetration-test planning, reconnaissance, scanning, exploitation, post-exploitation, pivoting, and password attacks.

Customer value

Supports systematic infrastructure testing connected to realistic attack paths.

View official GPEN information

GIAC

GWAPT

GIAC Web Application Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

GIAC พัฒนาและบริหารการรับรองวิชาชีพเฉพาะทางด้าน Information Security

ความสามารถที่สะท้อน

Authentication, Session, Configuration, SQL Injection, CSRF, XSS และ Client-side Injection

คุณค่าต่อลูกค้า

ช่วยเพิ่มความลึกในการทดสอบเว็บและเส้นทางโจมตีที่เชื่อมกับข้อมูลหรือบัญชีผู้ใช้

ดูข้อมูล GWAPT จาก GIAC

Issuer credibility

GIAC develops and administers specialist information-security certifications.

Demonstrated capability

Authentication, session, configuration, SQL injection, CSRF, XSS, and client-side injection testing.

Customer value

Adds depth to web assessments involving user accounts, sensitive data, and application attack paths.

View official GWAPT information

ISC2

CISSP

Certified Information Systems Security Professional

ความน่าเชื่อถือของผู้ออกใบรับรอง

ISC2 เป็นสมาคมสมาชิกไม่แสวงหากำไรสำหรับผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

Risk Management, Security Architecture, IAM, Security Assessment, Operations และ Secure Development

คุณค่าต่อลูกค้า

ช่วยแปลผลการทดสอบทางเทคนิคให้เชื่อมกับระดับความเสี่ยง สำหรับผู้ที่ต้องรับผิดชอบแก้ไข และบริบทการกำกับดูแลขององค์กร

ดูข้อมูล CISSP จาก ISC2

Issuer credibility

ISC2 is a nonprofit member association for cybersecurity professionals.

Demonstrated capability

Risk management, security architecture, IAM, assessment, operations, and secure development.

Customer value

Helps connect technical findings with business risk, remediation ownership, and security governance.

View official CISSP information

CREST

CREST CRT

CREST Registered Penetration Tester

ความน่าเชื่อถือของผู้ออกใบรับรอง

CREST เป็นองค์กรสมาชิกสากลที่ไม่แสวงหากำไร ซึ่งรับรององค์กรและผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

การทดสอบโครงสร้างพื้นฐาน เว็บ ระบบปฏิบัติการ Network Services การตีความผลสแกน และการยืนยันช่องโหว่

คุณค่าต่อลูกค้า

สนับสนุนงานทดสอบที่มีวินัยทางเทคนิคและสอดคล้องกับแนวทางวิชาชีพของ CREST

ดูข้อมูล CREST CRT

Issuer credibility

CREST is an international not-for-profit membership body that accredits cybersecurity organizations and certifies professionals.

Demonstrated capability

Infrastructure and web testing, operating systems, network services, scan interpretation, and vulnerability validation.

Customer value

Supports technically disciplined assessments aligned with CREST professional practice.

View official CREST CRT information

CREST

CREST CPSA

CREST Practitioner Security Analyst

ความน่าเชื่อถือของผู้ออกใบรับรอง

CREST เป็นองค์กรสมาชิกสากลที่ไม่แสวงหากำไร ซึ่งรับรององค์กรและผู้เชี่ยวชาญด้าน Cybersecurity

ความสามารถที่สะท้อน

Testing Lifecycle, Scoping, Windows, Unix, Network Services, Web Technologies และ Vulnerability Assessment

คุณค่าต่อลูกค้า

สนับสนุนการกำหนดขอบเขต การดำเนินการ และการตีความผลทดสอบอย่างสม่ำเสมอ

ดูข้อมูล CREST CPSA

Issuer credibility

CREST is an international not-for-profit membership body that accredits cybersecurity organizations and certifies professionals.

Demonstrated capability

Testing lifecycle, scoping, Windows, Unix, network services, web technologies, and vulnerability assessment.

Customer value

Supports consistent scoping, execution, and interpretation of security tests.

View official CREST CPSA information

Hack The Box Academy

HTB CWES

HTB Certified Web Exploitation Specialist

ความน่าเชื่อถือของผู้ออกใบรับรอง

Hack The Box ให้บริการ HTB Academy เป็นแพลตฟอร์มฝึกอบรม Cybersecurity แบบโต้ตอบและลงมือปฏิบัติจริง

ความสามารถที่สะท้อน

Web Application และ API Penetration Testing, Bug Bounty Methodology, Risk Evaluation และ Actionable Reporting

คุณค่าต่อลูกค้า

สนับสนุนการทดสอบเว็บและ API สมัยใหม่ด้วยทักษะที่ผ่านสถานการณ์ปฏิบัติจริง

ดูข้อมูลใบรับรองจาก Hack The Box Academy

Issuer credibility

Hack The Box operates HTB Academy, an interactive, hands-on cybersecurity training platform.

Demonstrated capability

Web-application and API penetration testing, bug-bounty methodology, risk evaluation, and actionable reporting.

Customer value

Supports practical assessment of modern web applications and APIs.

View official HTB Academy certification information

DECISION GATE / SCOPE

ขอบเขตและกติกาการทดสอบ Scope & Rules of Engagement

เราตกลงเป้าหมาย สิทธิ์ วิธีทดสอบ และจุดหยุดร่วมกันก่อนเริ่ม เพื่อให้การทดสอบลงลึกได้โดยควบคุมผลกระทบต่อธุรกิจ We agree targets, authority, test methods, and stop conditions before execution so the assessment can go deep while controlling business impact.

Scope and Rules of Engagement planning before testing begins

ระบบและสิทธิ์ที่ต้องเตรียม

ขอบเขตระบบและ Access สำหรับการทดสอบ
ระบบScopeAccess
เว็บและ APIDomains, routes, APIs, admin portals, roles และ integrationsบัญชีทดสอบ, MFA path, API documentation และ test data
แอปมือถือAndroid/iOS builds, package IDs, deep links, local storage และ backend APIsTest builds, devices, accounts, source หรือ symbols เมื่อตกลง
เครือข่ายภายนอกPublic IP ranges, DNS, VPN, gateways, cloud edge และ exposed servicesApproved source IPs, maintenance window และ emergency contacts
เครือข่ายภายในSubnets, hosts, Active Directory, identity, segmentation และ management servicesVPN/jump host, test workstation, test identities และ routing prerequisites

เลือกรูปแบบการทดสอบให้เหมาะกับเป้าหมาย

เปรียบเทียบ Black Box, Gray Box และ White Box
รูปแบบข้อมูลและสิทธิ์เหมาะกับคุณค่าต่อลูกค้า
ภาพประกอบ Black Boxให้ข้อมูลเป้าหมายสาธารณะขั้นต่ำมุมมองผู้โจมตีภายนอกยืนยัน Exposure ที่สมจริง
ภาพประกอบ Gray Boxให้บัญชีทดสอบและเอกสารที่จำเป็นRole, Business Logic และ Authenticated Pathsสมดุลความสมจริง ความลึก และเวลาส่งมอบ
ภาพประกอบ White Boxให้ Architecture, Source, Configuration และสิทธิ์ที่ตกลงCoverage และ Root-cause Analysis เชิงลึกมองเห็นเชิงเทคนิคและบริบทการแก้ไขสูงสุด

Rules of Engagement ที่ยืนยันก่อนเริ่ม

  • หนังสืออนุญาตและผู้อนุมัติที่ระบุชื่อ
  • ทรัพย์สินใน Scope และรายการที่ยกเว้น
  • เทคนิคที่อนุญาตและห้ามใช้
  • Test window, source IPs, rate limits และ stop conditions
  • การจัดการข้อมูล Production และอายุการเก็บหลักฐาน
  • ช่องทางยกระดับเหตุการณ์ Critical
  • การ Cleanup, ลบบัญชีทดสอบ และเงื่อนไข Revisit

Gate: พร้อมเริ่มเมื่อ Scope, Access, Test Window, ROE และช่องทาง Escalation ได้รับการยืนยัน

Systems and access to prepare

System scope and access required for testing
SystemScopeAccess
Web and APIDomains, routes, APIs, admin portals, roles, and integrationsTest accounts, MFA path, API documentation, and test data
MobileAndroid/iOS builds, package IDs, deep links, local storage, and backend APIsTest builds, devices, accounts, source, or symbols when agreed
External NetworkPublic IP ranges, DNS, VPN, gateways, cloud edge, and exposed servicesApproved source IPs, maintenance window, and emergency contacts
Internal NetworkSubnets, hosts, Active Directory, identity, segmentation, and management servicesVPN/jump host, test workstation, test identities, and routing prerequisites

Select the testing model that fits the objective

Black Box, Gray Box, and White Box comparison
ModelInformation and accessBest fitCustomer value
Black Box testing model illustrationMinimal public target informationAn external attacker viewRealistic exposure validation
Gray Box testing model illustrationTest accounts and selected documentationRoles, business logic, and authenticated pathsBalanced realism, depth, and delivery time
White Box testing model illustrationAgreed architecture, source, configuration, and accessDeep coverage and root-cause analysisMaximum technical visibility and remediation context

Rules of Engagement confirmed before testing

  • Written authorization and named approvers
  • In-scope and excluded assets
  • Allowed and prohibited techniques
  • Test window, source IPs, rate limits, and stop conditions
  • Production-data handling and evidence retention
  • Critical-event escalation
  • Cleanup, test-account removal, and revisit conditions

Gate: Ready to begin when scope, access, the test window, ROE, and escalation paths are confirmed.

DECISION GATE / ATTACK SURFACE

Attack Surface ที่เรานำไปทดสอบAttack Surface We Carry Into Testing

เปลี่ยนรายการระบบให้เป็นแผนที่ Entry Points, Trust Boundaries, Roles และเส้นทางเข้าถึงข้อมูลสำคัญTurn the asset inventory into a map of entry points, trust boundaries, roles, and paths to sensitive data.

Attack surface map for web, mobile, and network testing

Web และ API

พื้นผิวการโจมตีเว็บและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Entry points, routes, authentication และ sessionsOWASP WSTG v4.2; OWASP Top 10:2025
Object/function authorization, rate limits และ sensitive business flowsOWASP API Security Top 10:2023
Configuration, files, integrations, SSRF และ cloud storageWSTG v4.2 และ API Security
Authorized adversary behaviorsMITRE Enterprise ATT&CK T1595 Active Scanning และ T1190 Exploit Public-Facing Application

Mobile

พื้นผิวการโจมตีแอปมือถือและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Package, code, update path และ tamper resistanceMASVS 2.1 CODE/RESILIENCE; MASTG 2.0
Local storage, cryptography และ privacyMASVS-STORAGE, CRYPTO และ PRIVACY
Authentication, platform, deep links และ network trafficMASVS-AUTH, PLATFORM และ NETWORK
Backend APIs และพฤติกรรมที่เกี่ยวข้องAPI Top 10:2023; MITRE Mobile ATT&CK T1664, T1417, T1533

Network

พื้นผิวการโจมตีเครือข่ายและการอ้างอิง
พื้นที่ทดสอบการอ้างอิง
Public services, VPN, gateways และ cloud edgeT1595, T1133, T1190
Internal hosts และ service discoveryT1046
Identities และ trust pathsT1078
Remote-service exploitation, segmentation และ lateral pathsMITRE Enterprise ATT&CK Discovery และ Lateral Movement; T1210

Outputs

  • Asset และ endpoint inventory
  • Role และ privilege matrix
  • Data-flow และ trust-boundary map
  • Prioritized abuse cases และ attack paths
  • Assumptions และ exclusions

ATT&CK ใช้เป็นฐานความรู้พฤติกรรมผู้โจมตีสำหรับ Mapping เฉพาะเทคนิคที่ได้รับอนุญาต ทดสอบ และมีหลักฐาน ไม่ใช่มาตรฐานทดสอบหรือเปอร์เซ็นต์ Coverage

Gate: ยืนยัน High-value Assets, Trust Boundaries และ Attack Paths ที่มีเหตุผลเพียงพอสำหรับการทดสอบ

Web and API

Web attack surface and references
Test areaReference mapping
Entry points, routes, authentication, and sessionsOWASP WSTG v4.2; OWASP Top 10:2025
Object/function authorization, rate limits, and sensitive business flowsOWASP API Security Top 10:2023
Configuration, files, integrations, SSRF, and cloud storageWSTG v4.2 and API Security
Authorized adversary behaviorsMITRE Enterprise ATT&CK T1595 Active Scanning and T1190 Exploit Public-Facing Application

Mobile

Mobile attack surface and references
Test areaReference mapping
Package, code, update path, and tamper resistanceMASVS 2.1 CODE/RESILIENCE; MASTG 2.0
Local storage, cryptography, and privacyMASVS-STORAGE, CRYPTO, and PRIVACY
Authentication, platform, deep links, and network trafficMASVS-AUTH, PLATFORM, and NETWORK
Backend APIs and relevant behaviorAPI Top 10:2023; MITRE Mobile ATT&CK T1664, T1417, T1533

Network

Network attack surface and references
Test areaReference mapping
Public services, VPN, gateways, and cloud edgeT1595, T1133, T1190
Internal hosts and service discoveryT1046
Identities and trust pathsT1078
Remote-service exploitation, segmentation, and lateral pathsMITRE Enterprise ATT&CK Discovery and Lateral Movement; T1210

Outputs

  • Asset and endpoint inventory
  • Role and privilege matrix
  • Data-flow and trust-boundary map
  • Prioritized abuse cases and attack paths
  • Assumptions and exclusions

ATT&CK is adversary-behavior knowledge used to map authorized, tested, and evidenced techniques. It is not a testing standard or coverage percentage.

Gate: Confirm the high-value assets, trust boundaries, and justified attack paths selected for testing.

DECISION GATE / COVERAGE

Coverage ที่กว้างขึ้น หลักฐานที่มนุษย์รับผิดชอบBroader Coverage, Human-Owned Evidence

AI ทำ reconnaissance และทดสอบเชิงรุกอัตโนมัติภายใน Scope เพื่อเพิ่มความเร็วและความครอบคลุม ส่วนผู้เชี่ยวชาญควบคุมการทดสอบ ยืนยันผลกระทบ และอนุมัติทุก FindingAI performs reconnaissance and automated active testing within scope to increase speed and coverage; specialists control testing, validate impact, and approve every finding.

Specialists and AI working together to expand assessment coverage

AI ทดสอบ แต่ผู้เชี่ยวชาญจาก STH ตัดสินผล

บทบาท AI และ Human ตลอดการทดสอบ
ขั้นตอนAIHuman
PlanningNormalize รายการทรัพย์สิน เสนอ Coverage gaps และ reference mappingsอนุมัติ Scope, safety constraints, ลำดับ และความลึก
Testingทำ reconnaissance สร้างสมมติฐาน และทดสอบเชิงรุกอัตโนมัติภายใน Scopeควบคุมการทดสอบ วิเคราะห์ Business Logic และยืนยัน Exploitation
Validationจัดกลุ่ม Artifacts และช่วย Cross-referenceทำซ้ำ Finding, รัน negative control, ยืนยัน affected scope และผลกระทบ
Reportingช่วย Index หลักฐานและ Draft trace linksให้เหตุผลและอนุมัติถ้อยคำ Remediation, Severity และรายงานสุดท้าย

มาตรฐานหลักฐาน

  • Request/response หรือ command/output
  • Timestamp และ affected asset
  • Reproduction steps และ preconditions
  • Positive proof พร้อม negative control ที่เกี่ยวข้อง
  • ผลกระทบต่อข้อมูล สิทธิ์ และธุรกิจ
  • Sanitized screenshot, recording หรือ PoC
  • Reviewer และสถานะ

ลูกค้าได้ Coverage ที่เร็วและกว้างขึ้น โดยไม่ลดความรับผิดชอบ ความสามารถในการทำซ้ำ และคุณภาพของหลักฐาน

Gate: Finding เข้ารายงานเมื่อทำซ้ำได้ อยู่ใน Scope มีหลักฐานเพียงพอ อธิบายผลกระทบได้ และผ่าน Human Review

AI runs automated testing; humans remain accountable

AI and human roles across the assessment
PhaseAIHuman
PlanningNormalizes asset lists, suggests coverage gaps, and reference mappingsApproves scope, safety constraints, sequence, and test depth
TestingPerforms reconnaissance, generates hypotheses, and runs automated active testing within scopeControls testing, analyzes business logic, and validates exploitation
ValidationClusters artifacts and assists cross-reference checksReproduces findings, runs negative controls, and establishes scope and impact
ReportingAssists evidence indexing and draft trace linksAssigns rationale and approves wording, remediation, severity, and the final report

Evidence standard

  • Request/response or command/output
  • Timestamp and affected asset
  • Reproduction steps and preconditions
  • Positive proof plus a relevant negative control
  • Data, privilege, and business impact
  • Sanitized screenshot, recording, or PoC
  • Reviewer and status

Gain faster, broader coverage without reducing accountability, reproducibility, or evidence quality.

Gate: A finding enters the report only when it is reproducible, in scope, sufficiently evidenced, impact-backed, and human-reviewed.

DECISION GATE / RISK

เหตุผลเบื้องหลังระดับความเสี่ยงHow We Build the Risk Rationale

แยกความรุนแรงทางเทคนิคออกจากความเสี่ยงทางธุรกิจ แล้วแสดงสมมติฐาน คะแนน และ Vector ให้ตรวจสอบย้อนกลับได้Separate technical severity from business risk and expose the assumptions, score, and vector for traceability.

Conceptual risk rating from likelihood and impact

OWASP Risk Rating

Risk = Likelihood × Impact

Factors และเกณฑ์การให้คะแนน 0-9
องค์ประกอบFactorsเกณฑ์
LikelihoodThreat agent: skill, motive, opportunity, size; Vulnerability: discovery, exploit, awareness, detectionLow <3, Medium 3-<6, High 6-9
ImpactTechnical: confidentiality, integrity, availability, accountability; Business: financial, reputation, compliance, privacyLow <3, Medium 3-<6, High 6-9

เราให้คะแนนปัจจัยที่เกี่ยวข้อง แล้ววางผลลงในตาราง Likelihood-Impact เพื่อให้เห็นระดับความเสี่ยง จากนั้นจึงทบทวนตามบริบทธุรกิจและมาตรการที่ลูกค้ามีอยู่ หากยังไม่มีข้อมูลธุรกิจ เราจะใช้ผลกระทบทางเทคนิคเป็นฐานและบันทึกสมมติฐานไว้ในรายงาน

CVSS v4.0

แผนภาพกลุ่ม Metric ของ CVSS v4.0: Base, Threat, Environmental และ Supplemental
Metric groups ที่ใช้คำนวณ
กลุ่มMetrics
BaseAV, AC, AT, PR, UI และผลกระทบ CIA ต่อ Vulnerable/Subsequent Systems
ThreatExploit Maturity
EnvironmentalSecurity requirements และ Modified Base metrics สำหรับสภาพแวดล้อมลูกค้า
SupplementalSafety, automation, recovery, value density, response effort และ provider urgency ใช้เป็นบริบทและไม่เปลี่ยนคะแนน

CVSS ช่วยบอกระดับความรุนแรงของช่องโหว่ด้วยมาตรฐานเดียวกัน ตั้งแต่ 0.0-10.0 รายงานของ STH ระบุทั้งคะแนน ระดับความรุนแรง และ CVSS Vector เพื่อให้ทีมเทคนิคตรวจสอบหรือเปรียบเทียบผลได้ เราใช้เครื่องมืออ้างอิงของ FIRST ตามมาตรฐาน CVSS v4.0 เพื่อให้คะแนนโปร่งใสและสอดคล้องกัน

Remediation priority

เราเรียงลำดับการแก้ไขจากความรุนแรงทางเทคนิค ความเป็นไปได้ที่โจมตีได้จริง ความสำคัญของระบบหรือข้อมูล ผลกระทบต่อธุรกิจของลูกค้า และมาตรการควบคุมที่มีอยู่ พร้อมบันทึกเหตุผลของแต่ละลำดับไว้ชัดเจน

ผู้บริหารเห็นเหตุผลของลำดับความสำคัญ ส่วนทีมเทคนิคเห็น Metrics และหลักฐานที่ใช้ตัดสิน

Gate: ยืนยันสถานะ Finding, CVSS Vector, OWASP Risk Rationale, Business Context และ Remediation Priority

OWASP Risk Rating

Risk = Likelihood × Impact

Factors and 0-9 thresholds
ComponentFactorsThresholds
LikelihoodThreat agent: skill, motive, opportunity, size; Vulnerability: discovery, exploit, awareness, detectionLow <3, Medium 3-<6, High 6-9
ImpactTechnical: confidentiality, integrity, availability, accountability; Business: financial, reputation, compliance, privacyLow <3, Medium 3-<6, High 6-9

We score the relevant factors and place the result on the likelihood-impact matrix to make the risk level clear. We then review it against the customer’s business context and existing controls. If business data is unavailable, we use technical impact as the baseline and document the assumption.

CVSS v4.0

Diagram of CVSS v4.0 metric groups: Base, Threat, Environmental, and Supplemental
Metric groups used in calculation
GroupMetrics
BaseAV, AC, AT, PR, UI and vulnerable/subsequent-system CIA impacts
ThreatExploit Maturity
EnvironmentalSecurity requirements and Modified Base metrics for the customer environment
SupplementalSafety, automation, recovery, value density, response effort, and provider urgency are contextual only and do not change the score

CVSS gives every vulnerability a severity score on the same 0.0-10.0 scale. STH reports the score, severity rating, and CVSS vector so technical teams can validate or compare the result. We use FIRST’s CVSS v4.0 reference calculator to keep scoring consistent and transparent.

Remediation priority

We prioritize remediation by considering technical severity, verified exploitability, the importance of affected systems or data, customer business impact, and existing controls. The rationale for each priority is documented clearly.

Executives see why remediation is prioritized; technical teams see the metrics and evidence behind the decision.

Gate: Confirm finding status, CVSS vector, OWASP risk rationale, business context, and remediation priority.

DECISION GATE / REPORT

จากหลักฐานสู่รายงานที่ลงมือแก้ได้From Evidence to an Actionable Report

รายงานชุดเดียวสื่อสารได้ทั้งกับผู้บริหาร เจ้าของระบบ และทีมที่ลงมือแก้ไขOne report set communicates clearly to executives, system owners, and remediation teams.

Sample STH penetration testing report cover

Report anatomy

  1. Cover Classification, ลูกค้า, Engagement, Version และวันที่
  2. Executive Summary ภาพรวมผลกระทบทางธุรกิจ
  3. Scope & ROE ระบบ ข้อยกเว้น Access model และกติกา
  4. Methodology Standard และ Coverage matrix
  5. Risk overview Findings ที่จัดลำดับแล้ว
  6. Finding Details ID, Assets, Status, Risk, CVSS score/vector, Evidence, Impact และ Remediation
  7. Attack chain ความสัมพันธ์ของ Findings
  8. Recommended Solutions Roadmap และผู้รับผิดชอบแก้ไข
  9. Appendix Evidence และ Framework traceability

Initial Report และ Revisit Report

ความแตกต่างของรายงานก่อนและหลังการแก้ไข
รายงานเนื้อหาหลักหลักฐานและผลลัพธ์
Initial ReportScope/วันที่ทดสอบ, Initial risk snapshot, Findings และคำแนะนำหลักฐานครบ, Remediation และ Ownership
Revisit ReportRetest scope/date/version พร้อม Finding ID และ Risk เดิมสถานะ Closed, Partially Remediated, Open, Unable to Verify หรือ Risk Accepted; Before/after evidence, bypass results และ residual risk

Gate: ยืนยันข้อเท็จจริง ผู้รับผิดชอบแก้ไข ลำดับความสำคัญ และรายการที่ต้องเข้าสู่ Revisit

Report anatomy

  1. Cover Classification, customer, engagement, version, and date
  2. Executive Summary Business impact at a glance
  3. Scope & ROE Systems, exclusions, access model, and rules
  4. Methodology Standards and coverage matrix
  5. Risk overview Prioritized findings
  6. Finding Details ID, assets, status, risk, CVSS score/vector, evidence, impact, and remediation
  7. Attack chain Relationships between findings
  8. Recommended Solutions Roadmap and remediation ownership
  9. Appendix Evidence and framework traceability

Initial Report and Revisit Report

Initial and post-remediation reporting
ReportCore contentEvidence and outcome
Initial ReportOriginal scope and dates, initial risk snapshot, findings, and recommendationsComplete evidence, remediation, and ownership
Revisit ReportRetest scope/date/version with original finding ID and riskClosed, Partially Remediated, Open, Unable to Verify, or Risk Accepted; before/after evidence, bypass results, and residual risk

Gate: Confirm facts, remediation owners, priorities, and items requiring revisit.

LEGAL & PRIVACY / 01

นโยบายความเป็นส่วนตัว Privacy Policy

ปรับปรุงล่าสุด 13 กรกฎาคม 2026

เราให้ความสำคัญกับการรักษาความเป็นส่วนตัวของผู้เข้าชมเว็บไซต์ นโยบายนี้อธิบายวิธีที่เว็บไซต์ประมวลผลข้อมูลและสิทธิของคุณเกี่ยวกับข้อมูลส่วนบุคคล

ข้อมูลที่เว็บไซต์เก็บรวบรวม

เว็บไซต์นี้ไม่เก็บข้อมูลส่วนบุคคลที่สามารถระบุตัวตนของผู้เข้าชมโดยอัตโนมัติ ข้อมูลที่ผู้ใช้ส่งผ่านแบบฟอร์มขอใบเสนอราคาจะใช้เพื่อประเมินขอบเขตโครงการ จัดทำข้อเสนอ และติดต่อกลับตามความยินยอมที่ผู้ใช้ให้ไว้

คุกกี้ที่เว็บไซต์ใช้

ฟังก์ชัน LINE

วิดเจ็ต LINE เป็นฟังก์ชันจากบุคคลที่สามและจะไม่ถูกโหลดจนกว่าคุณจะอนุญาตคุกกี้ฟังก์ชัน คุณเปลี่ยนหรือถอนความยินยอมได้จากปุ่มตั้งค่าคุกกี้ท้ายหน้า โดยยังใช้ลิงก์ LINE โดยตรงและสแกน QR Code ที่เว็บไซต์จัดเตรียมไว้ได้โดยไม่ต้องโหลดวิดเจ็ต

Cloudflare Web Analytics

เมื่อคุณอนุญาตคุกกี้วัดผล เว็บไซต์จะโหลด Cloudflare Web Analytics เพื่อช่วยให้เราเข้าใจการใช้งานเว็บไซต์ในภาพรวม เราจะไม่โหลดสคริปต์นี้หากคุณเลือกใช้เฉพาะคุกกี้ที่จำเป็น และคุณสามารถเปลี่ยนหรือถอนความยินยอมได้จากปุ่มตั้งค่าคุกกี้ท้ายหน้า อ่านรายละเอียดได้ที่ Cloudflare Privacy Policy

การเพิ่มประสิทธิภาพและรักษาความปลอดภัยเว็บไซต์

เมื่อให้บริการบนระบบ production เราอาจใช้ Cloudflare เพื่อเพิ่มประสิทธิภาพและป้องกันการโจมตี โดย Cloudflare อาจประมวลผลข้อมูลทางเทคนิคหรือวางคุกกี้ที่จำเป็นต่อการให้บริการ อ่านรายละเอียดได้ที่ Cloudflare Privacy Policy

ลิงก์ไปยังเว็บไซต์ภายนอก

เว็บไซต์อาจมีลิงก์ไปยังเว็บไซต์อื่น เมื่อคุณออกจากเว็บไซต์ของเรา เราไม่สามารถควบคุมหรือรับผิดชอบต่อการคุ้มครองข้อมูลของเว็บไซต์ภายนอกได้ โปรดตรวจสอบนโยบายความเป็นส่วนตัวของเว็บไซต์นั้นก่อนให้ข้อมูล

การเปลี่ยนแปลงนโยบาย

เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราว โดยจะแสดงวันที่ปรับปรุงล่าสุดไว้ด้านบน การเปลี่ยนแปลงมีผลเมื่อเผยแพร่บนเว็บไซต์นี้

ข้อมูลติดต่อ

หากมีคำถามเกี่ยวกับนโยบายความเป็นส่วนตัว ติดต่อ privacy@sth.sh

Last updated on July 13, 2026

We are committed to safeguarding and preserving the privacy of our website visitors. This policy explains how the website processes information and informs you of your rights regarding personal data.

Information Collected By Our Website

This website does not automatically collect personally identifiable information from visitors. Information submitted through the quotation form is used to assess project scope, prepare a proposal, and contact the requester under the consent they provide.

Cookies Used By Our Website

LINE Functionality

The third-party LINE widget is not loaded until you allow functional cookies. You can change or withdraw consent from Cookie settings in the footer. The first-party direct LINE link and QR code remain available without loading the widget.

Cloudflare Web Analytics

When you allow analytics cookies, the website loads Cloudflare Web Analytics to help us understand overall site usage. This script is not loaded when you choose essential cookies only, and you can change or withdraw consent from Cookie Settings in the footer. Read the Cloudflare Privacy Policy for details.

Site Optimization And Security

When deployed to production, we may use Cloudflare to optimize and protect the site. Cloudflare may process technical data or place cookies that are necessary to provide these services. Read the Cloudflare Privacy Policy for details.

Third Party Links

Our website may contain links to other websites. Once you leave our site, we do not control and cannot be responsible for how another website protects your information. Please review the privacy statement applicable to that website before providing information.

Changes To This Privacy Policy

We may update this Privacy Policy from time to time. The latest revision date appears at the top of this policy, and changes become effective when they are posted on this website.

Contact Information

If you have questions regarding this privacy policy, contact privacy@sth.sh.

QMS & ISMS / 02

นโยบายคุณภาพและความมั่นคงปลอดภัยสารสนเทศ Quality and Information Security Policy

ปรับปรุงล่าสุด 26 พฤศจิกายน 2025

บริษัท สยามถนัดแฮก จำกัด ผสานการบริหารคุณภาพและความมั่นคงปลอดภัยสารสนเทศไว้ในกระบวนการดำเนินงานหลัก เรามุ่งให้บริการ Cyber Security ที่มีความแม่นยำ พร้อมปกป้องข้อมูลที่ได้รับความไว้วางใจจากลูกค้า

นโยบายคุณภาพ (ISO 9001:2015)

เรามุ่งให้บริการ Penetration Testing และงานที่ปรึกษาที่ถูกต้อง นำไปใช้ได้จริง และเป็นไปตามมาตรฐานวิชาชีพ โดยยึดหลักดังต่อไปนี้

  • ส่งมอบผลการประเมินที่มีหลักฐาน เพื่อให้ลูกค้าระบุและแก้ไขช่องโหว่ได้อย่างแม่นยำ
  • ตอบสนองหรือก้าวเกินความคาดหวังของลูกค้าด้วยการส่งมอบตรงเวลา การสื่อสารชัดเจน และคำปรึกษาจากผู้เชี่ยวชาญ
  • พัฒนาความรู้และทักษะของทีมเทคนิคอย่างต่อเนื่องให้ทันต่อเทคโนโลยีและรูปแบบการโจมตีใหม่
  • ประเมินและปรับปรุงกระบวนการดำเนินงานอย่างต่อเนื่อง เพื่อเพิ่มประสิทธิภาพและคุณภาพบริการ

นโยบายความมั่นคงปลอดภัยสารสนเทศ (ISO/IEC 27001:2022)

เราให้ความสำคัญกับการปกป้องทรัพย์สินสารสนเทศของลูกค้า คู่ค้า และองค์กร โดยควบคุมการรักษาความลับ ความถูกต้องครบถ้วน และความพร้อมใช้งานของข้อมูล

  • ปกป้องทรัพย์สินทางปัญญาและข้อมูลสำคัญจากการเข้าถึง การรั่วไหล หรือการแก้ไขโดยไม่ได้รับอนุญาต
  • ระบุ ประเมิน และจัดการความเสี่ยงที่เกี่ยวข้องกับบุคลากร กระบวนการ และเทคโนโลยีเชิงรุก
  • ดำเนินงานตามกฎหมายที่เกี่ยวข้อง รวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล (PDPA) และข้อกำหนดด้าน Cyber Security
  • รักษาแผนตอบสนองเหตุการณ์และความต่อเนื่องทางธุรกิจ เพื่อให้องค์กรพร้อมรับมือเหตุการณ์ด้านความปลอดภัย

การสื่อสารและทบทวนนโยบาย

นโยบายนี้สื่อสารแก่พนักงานและผู้มีส่วนได้ส่วนเสีย และได้รับการทบทวนอย่างน้อยปีละครั้ง เพื่อให้สอดคล้องกับทิศทางองค์กรและภัยคุกคามที่เปลี่ยนแปลง

การรายงานเหตุการณ์ด้านความปลอดภัย

หากพบประเด็นด้านความปลอดภัยในระบบของเรา โปรดรายงานโดยตรงที่ security@sth.sh เราจะตอบรับรายงานภายใน 24 ชั่วโมง

Last updated on November 26, 2025

Siam Thanat Hack Co., Ltd. integrates quality management and information security into the core of our operations. We are dedicated to delivering precision-driven cybersecurity services while safeguarding the data entrusted to us.

Quality Policy (ISO 9001:2015)

We are committed to providing professional penetration testing and consultancy services that are accurate, actionable, and meet the highest professional standards. We adhere to the following principles:

  • Deliver evidence-based security assessments that allow clients to identify and remediate vulnerabilities effectively and precisely.
  • Consistently meet or exceed client expectations through timely delivery, clear communication, and expert consultation.
  • Ensure our technical team maintains industry-leading qualifications and continually updates its skills to match emerging technologies and attack vectors.
  • Continuously evaluate and refine our operational processes to maximize efficiency and service quality.

Information Security Policy (ISO/IEC 27001:2022)

We prioritize the protection of information assets belonging to our clients, partners, and our organization. We enforce controls to ensure the Confidentiality, Integrity, and Availability of data across all operations.

  • Rigorously protect intellectual property and sensitive data from unauthorized access, leakage, or tampering.
  • Proactively identify, evaluate, and mitigate security risks associated with our people, processes, and technology.
  • Operate in accordance with applicable laws, including the Personal Data Protection Act (PDPA), and relevant cybersecurity regulations.
  • Maintain robust incident response and business continuity plans to ensure resilience against security events.

Policy Communication & Review

This policy is communicated to employees and stakeholders to ensure a shared understanding of our standards. It is reviewed at least annually to remain aligned with our strategic direction and the evolving cybersecurity landscape.

Reporting Security Incidents

If you identify a security issue within our systems, report it directly to security@sth.sh. We acknowledge all security reports within 24 hours.

INFORMATION SECURITY MANAGEMENT

ISO/IEC 27001:2022 and Penetration Testing

An information security management system (ISMS) standard for systematically managing risks to information, people, processes, and technology.

Requirements related to Penetration Testing

  • ISO/IEC 27001:2022 does not require every organization to conduct Penetration Testing on a fixed schedule. It requires organizations to identify, assess, and treat information security risks systematically.
  • Penetration Testing can provide a control activity and supporting evidence for Annex A 8.8 technical vulnerability management, A.8.29 security testing in development and acceptance, and A.5.35 independent review of information security.
  • Scope and frequency should be based on risk assessment results, legal, regulatory, and contractual obligations, and system criticality.
  • Test results should feed risk treatment, remediation, risk acceptance, and evidence of continual ISMS improvement.
Key point

ISO/IEC 27001 is a risk-based standard, not a test-case list. Penetration Testing should therefore be tied to each organization's risks and Statement of Applicability.

Open ISO/IEC 27001:2022 information from ISO

WEB APPLICATION RISK AWARENESS

OWASP Top 10 and Penetration Testing

An awareness document representing broad consensus on critical web application risks, helping organizations prioritize what to prevent and assess.

Reference versions by system type

Web Application - OWASP Top 10:2025
Mobile - OWASP Mobile Top 10 2024
API - OWASP API Security Top 10 2023
LLM - OWASP Top 10 for LLM Applications 2025

How it relates to Penetration Testing

  • Testers use these categories to plan coverage and map findings to risk language shared by developers, executives, and auditors.
  • The OWASP Top 10 is not a testing standard or a checklist covering every test case, and it should not replace a Penetration Testing methodology.
  • A sound assessment should use OWASP WSTG and ASVS alongside tests for business logic, APIs, authentication, authorization, and system-specific context.
Key point

Finding no OWASP Top 10 issues does not mean a system is risk-free. Scope and test cases must always reflect the real attack surface.

THREAT-INFORMED SECURITY

MITRE ATT&CK® and Penetration Testing

A knowledge base of observed adversary behavior, organized into tactics and techniques as a shared language for security work.

บทบาทในการทดสอบ

  • ATT&CK ช่วยให้ทีมทดสอบเลือกพฤติกรรมผู้โจมตีที่สอดคล้องกับ threat model, attack surface และความสำคัญของระบบ
  • สามารถใช้จัดทำ adversary emulation plan, เชื่อมโยงหลักฐานกับพฤติกรรมการโจมตี และสื่อสารช่องว่างการป้องกัน การตรวจจับ และการตอบสนอง

กำหนด coverage จากความเสี่ยงจริง

  • การ map ผลทดสอบเข้ากับ ATT&CK ช่วยสร้างความเชื่อมโยงย้อนกลับได้ แต่ไม่ได้พิสูจน์ว่าทดสอบครบทุกเทคนิคหรือครอบคลุมความเสี่ยง 100%
  • ขอบเขตต้องพิจารณาบริบทธุรกิจ สถาปัตยกรรม และข้อมูล threat intelligence ที่เกี่ยวข้อง ไม่ใช่เลือก test cases จากตารางเพียงอย่างเดียว
ขอบเขตของกรอบความรู้

ATT&CK เป็นฐานความรู้และแบบจำลองพฤติกรรมผู้โจมตีที่สังเกตได้ ไม่ใช่หน่วยงานกำกับดูแล มาตรฐาน ใบรับรอง หรือ checklist ที่รับประกัน coverage 100%

เปิด MITRE ATT&CK Resources

Role in testing

  • ATT&CK helps testing teams select observed adversary behaviors relevant to the threat model, attack surface, and criticality of the system.
  • It can inform adversary-emulation plans, map evidence to attacker behavior, and communicate gaps across protection, detection, and response.

Derive coverage from actual risk

  • Mapping test results to ATT&CK improves traceability; it does not prove that every technique was tested or that risk coverage is 100%.
  • Scope must reflect business context, architecture, and relevant threat intelligence rather than selecting test cases from the matrix alone.
Knowledge-base boundary

ATT&CK is a knowledge base and model of observed adversary behavior. It is not a regulator, standard, certification, or a 100%-coverage checklist.

Open MITRE ATT&CK Resources

PERSONAL DATA PROTECTION

Personal Data Protection Act B.E. 2562 (2019) and Penetration Testing

Section 37 requires data controllers to provide appropriate security measures. Penetration Testing is one way to validate the effectiveness of technical controls.

หน้าที่ตามมาตรา 37

  • ผู้ควบคุมข้อมูลส่วนบุคคลต้องมีมาตรการที่เหมาะสม เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยโดยปราศจากอำนาจหรือโดยมิชอบ
  • มาตรการขั้นต่ำต้องมีมาตรการเชิงองค์กรและเชิงเทคนิค และอาจรวมมาตรการทางกายภาพเมื่อจำเป็นตามระดับความเสี่ยง โดยต้องทบทวนเมื่อจำเป็นหรือเมื่อเทคโนโลยีเปลี่ยนแปลง

บทบาทของ Penetration Testing

  • ใช้ทดสอบว่าการควบคุมทางเทคนิคของ Web, Mobile, API, Network และ Cloud สามารถป้องกันการเข้าถึงหรือเปิดเผยข้อมูลโดยมิชอบได้จริงหรือไม่
  • การทดสอบต้องได้รับอนุญาต กำหนดขอบเขตตามความเสี่ยง ลดการเก็บข้อมูลส่วนบุคคลที่ไม่จำเป็น ปกปิดหลักฐาน และกำหนดการเก็บรักษาและลบที่ชัดเจน
ไม่ใช่หลักฐานทั้งหมดของ compliance

มาตรา 37 และประกาศมาตรการรักษาความมั่นคงปลอดภัยไม่ได้กำหนดให้ทำ Penetration Testing ปีละ 1 ครั้ง และผลทดสอบเพียงอย่างเดียวไม่ใช่หลักฐานว่าปฏิบัติตาม PDPA ครบถ้วน

Section 37 duty

  • A data controller must provide appropriate security measures to prevent unauthorized or unlawful loss, access, use, alteration, correction, or disclosure of personal data.
  • Minimum safeguards must include organizational and technical measures and may include physical measures where necessary according to risk. They must be reviewed when necessary or when technology changes.

Role of Penetration Testing

  • Testing can validate whether technical controls across web, mobile, API, network, and cloud environments resist unauthorized access or disclosure in practice.
  • Assessments must be authorized and risk-based, minimize unnecessary personal-data collection, redact evidence, and define secure retention and deletion.
Not complete compliance evidence

The PDPA does not mandate annual Penetration Testing. Section 37 and the security-measures notification require appropriate measures, while testing is one way to validate technical controls; a test report alone is not evidence of complete PDPA compliance.

NATIONAL CYBERSECURITY / RISK & AUDIT

Cybersecurity Act B.E. 2562 (2019) and Penetration Testing

The Act establishes cybersecurity risk-assessment and audit duties. Penetration Testing is a technical method and source of evidence that may support those duties; it is not the entire audit.

หน้าที่ตามพระราชบัญญัติ

  • มาตรา 44 กำหนดให้หน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) จัดทำประมวลแนวทางปฏิบัติและกรอบมาตรฐาน โดยอย่างน้อยต้องมีแผนการตรวจสอบและประเมินความเสี่ยงด้านการรักษาความมั่นคงปลอดภัยไซเบอร์ประจำปี
  • มาตรา 54 กำหนดให้หน่วยงาน CII จัดให้มีการประเมินความเสี่ยงและการตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์อย่างน้อยปีละหนึ่งครั้ง และส่งผลสรุปให้สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติภายในสามสิบวันนับแต่วันที่ดำเนินการแล้วเสร็จ

บทบาทของ Penetration Testing

  • Penetration Testing เป็นหลักฐานทางเทคนิคที่ช่วยสนับสนุนการประเมินความเสี่ยงและการตรวจสอบ แต่ไม่ใช่การตรวจสอบด้านความมั่นคงปลอดภัยไซเบอร์ทั้งหมด
  • ประมวลแนวทางปฏิบัติและกรอบมาตรฐาน พ.ศ. 2564 ข้อ 21.3.4 และ 21.3.6 ใช้ถ้อยคำเชิงแนะนำให้พิจารณา Penetration Testing ตามความเสี่ยงและความจำเป็น โดยเน้นบริการสำคัญและระบบที่เชื่อมต่ออินเทอร์เน็ต
  • หากดำเนินการ ขอบเขตควรครอบคลุม Host, Network และ Application ที่เกี่ยวข้อง และผู้ทดสอบควรมีความเป็นอิสระจากระบบและกระบวนการที่ถูกทดสอบ
ขอบเขตข้อกำหนด

พระราชบัญญัติไม่ได้กำหนดให้ทุกองค์กรต้องทำ Penetration Testing ทุกปี ต้องแยกหน้าที่ตรวจสอบและประเมินความเสี่ยงตามกฎหมายออกจากวิธีทดสอบทางเทคนิคที่เลือกใช้

Statutory duties

  • Section 44 requires government agencies, regulators or supervisors, and critical information infrastructure (CII) organizations to create a code of practice and standards framework whose minimum content includes an annual cybersecurity inspection and risk-assessment plan.
  • Section 54 specifically requires CII organizations to arrange a cybersecurity risk assessment and cybersecurity audit at least annually, then send a summary to NCSA within thirty days after completion.

Role of Penetration Testing

  • Penetration Testing is technical evidence supporting risk assessment and audit, not the whole audit.
  • Clauses 21.3.4 and 21.3.6 of the B.E. 2564 (2021) Code of Practice use recommendatory risk-and-need wording for Penetration Testing, focusing on critical and Internet-facing services.
  • When performed, scope should cover the relevant host, network, and application layers, and testers should be independent of the systems and processes under assessment.
Requirement boundary

The Act does not require every organization to conduct annual Penetration Testing. Keep the statutory risk-assessment and audit duties distinct from the technical testing method selected to support them.

BANK OF THAILAND / SECURITY ASSESSMENT

Bank of Thailand Penetration Testing Guideline

A prioritized summary of direct VA and Penetration Testing requirements, Mobile Banking security controls, and the supporting iPentest guideline.

1. SorNorChor. 1/2564 - direct VA and Penetration Testing requirements

  • Clause 5.1.6 requires vulnerability assessments for all systems according to risk at least annually and after significant changes.
  • Independent experts must conduct Penetration Testing of Internet-facing applications and networks at least annually and after every significant change.
  • This requirement forms part of Cyber Hygiene for regulated payment system and payment service operators within the notification's scope.

2. BOT Circular 1218/2568 / Notification 4/2568 - Mobile Banking Security

  • It applies to all financial institutions under the Financial Institution Business Act that provide Mobile Banking as defined by the notification.
  • It establishes minimum Mobile Banking controls including secure protocols and certificate pinning, anti-tampering, session security, source code obfuscation, and rooted or jailbroken device detection.
  • Use these controls as a baseline when defining Mobile Application Penetration Testing scope and test cases, while confirming the current notification and checklist used by your organization.

3. iPentest - supporting guidance for intelligence-led testing

  • Use threat intelligence to create scenarios and scope critical functions, including protection, detection, and response processes.
  • Use it for deeper readiness assessment beyond routine VA and Penetration Testing, with rigorous control of risk, scope, timing, and communications.
Applicability

The three documents have different regulated audiences and purposes. Before defining scope for a BOT submission, confirm the latest notification, circular, checklist, and reporting format with your organization's Compliance team.

SECURITIES AND EXCHANGE COMMISSION

SEC Penetration Testing Requirements

Information technology requirements for regulated businesses, designed to ensure important systems are appropriately tested, reported, and remediated.

Core Penetration Testing requirements

  • Internet-facing application systems and networks must be tested at least annually and whenever they undergo a significant change.
  • Other systems require an assessment of intrusion risk through internal networks to determine an appropriate testing scope.
  • Testing must be performed by an internal or external specialist independent of the system owner and development. Scanner-only testing is a vulnerability assessment and cannot replace Penetration Testing.
  • Identified vulnerabilities must be remediated and mitigated promptly. Reports must be retained for at least two years and provided to the SEC on request.
  • Reports should identify the tester, date, scope, vulnerabilities, detection methods, risk ratings, and recommended remediation.
Applicability

Applicable requirements depend on the business's licence and governing notices. Confirm them with Compliance or legal counsel before defining scope.

STRICT DISCLOSURE & ETHICS

Confidential & Authorized

Every assessment must be authorized, clearly scoped, confidential, and conducted without damaging or disrupting business operations.

Confidentiality and ethics principles

  • Begin testing only with written authorization and mutually agreed scope and Rules of Engagement. Never access systems, people, or data outside scope.
  • Restrict access to client information, findings, and evidence on a need-to-know basis. Use encrypted transfer and storage with defined retention and deletion periods.
  • Define testing windows, request rates, stop conditions, and emergency contacts. Avoid destructive tests, data modification, and persistence unless explicitly approved.
  • Collect only necessary evidence, redact personal and commercially sensitive information, and report only results reproduced and confirmed by an expert.
  • Never disclose, exploit, or share client information or vulnerabilities without authorization. Keep AI use under human control and never send client data to public AI services.
Safety First

Penetration Testing should prove risk safely and provide actionable remediation information, never cause damage, disrupt services, or increase business risk.

Report a vulnerability responsibly to pentest@sth.sh

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD

PCI DSS v4.0.1 and Penetration Testing

The security standard for entities that store, process, transmit, or can affect the security of payment card data.

ข้อกำหนดที่เกี่ยวข้องกับ Penetration Testing

  • PCI DSS ออกโดย PCI Security Standards Council และใช้กับ Merchant, Acquirer, Issuer, Processor และ Service Provider ที่อยู่ในขอบเขต Cardholder Data Environment (CDE)
  • Requirement 11.4 กำหนดการทดสอบภายในและภายนอกอย่างน้อยทุก 12 เดือน และหลังการอัปเกรดหรือเปลี่ยนแปลงโครงสร้างพื้นฐานหรือแอปพลิเคชันที่มีนัยสำคัญ
  • วิธีทดสอบต้องครอบคลุม Network และ Application layer รวมถึงช่องโหว่และภัยคุกคามที่เกิดขึ้นในช่วง 12 เดือนที่ผ่านมา พร้อมแก้ไขช่องโหว่ที่ใช้โจมตีได้และ Retest เพื่อยืนยันผล
  • หากใช้ Network Segmentation เพื่อลดขอบเขต PCI DSS ต้องทดสอบประสิทธิผลของการแบ่งส่วนตามความถี่และเงื่อนไขที่มาตรฐานกำหนด
ก่อนใช้ยื่น Compliance

ขอบเขต ความถี่ ผู้ทดสอบ และหลักฐานขึ้นอยู่กับประเภทองค์กรและวิธีประเมิน เช่น SAQ หรือ ROC ควรยืนยัน PCI DSS v4.0.1 ฉบับปัจจุบันกับ QSA หรือ Compliance ขององค์กร

เปิด PCI SSC Document Library

Penetration Testing requirements

  • PCI DSS is published by the PCI Security Standards Council and applies to merchants, acquirers, issuers, processors, and service providers within the Cardholder Data Environment (CDE).
  • Requirement 11.4 requires internal and external testing at least once every 12 months and after significant infrastructure or application upgrades or changes.
  • The methodology must address network and application layers, including vulnerabilities and threats experienced during the previous 12 months. Exploitable findings must be corrected and retested.
  • When network segmentation is used to reduce PCI DSS scope, its effectiveness must be tested at the frequency and under the conditions specified by the standard.
Before a compliance submission

Scope, frequency, tester qualification, and evidence depend on the entity and assessment method, such as SAQ or ROC. Confirm the current PCI DSS v4.0.1 text with your QSA or Compliance team.

Open the PCI SSC Document Library

NATIONAL DIGITAL ID

Penetration Testing Requirements for NDID Members

NDID is infrastructure for digital identity proofing and authentication that connects participating service providers in different roles.

สิ่งที่สมาชิกต้องเตรียมสำหรับ Security Assessment

  • ทดสอบระบบ Application, Web, Network layer และ Operating System ของสมาชิกที่เกี่ยวข้องกับระบบที่เชื่อมต่อกับ NDID Platform โดยไม่รวม NDID Node เว้นแต่เกณฑ์ที่ได้รับระบุเป็นอย่างอื่น
  • เกณฑ์ onboarding ที่ผู้ใช้ให้มาระบุให้ใช้ผู้ทดสอบจากนิติบุคคลภายนอก และแนบหลักฐานคุณสมบัติผู้ทดสอบ เช่น GPEN, eCPPT, OSCP หรือใบรับรองอื่นตามรายการที่ NDID ยอมรับสำหรับบทบาทนั้น
  • แนวทางทดสอบอ้างอิง OSSTMM หรือ NIST SP 800-115 ร่วมกับ OWASP Web/Mobile Testing Guide หรือใช้ PTES/ISSAF ตามเกณฑ์ฉบับที่ NDID ส่งให้สมาชิก
  • Critical, High และ Medium ต้องได้รับการแก้ไข ส่วน Low ต้องแก้ไขหรือบันทึกเหตุผล พร้อม Retest ช่องโหว่ที่แก้ไขแล้ว
  • จัดส่ง Final Penetration Test Report และใบรับรองผู้ทดสอบให้ NDID พิจารณา โดยเกณฑ์ที่ให้มาระบุความถี่อย่างน้อยปีละครั้งและหลัง Significant Change
ยืนยัน Criteria ล่าสุด

รายละเอียดอาจแตกต่างตามบทบาทสมาชิกและ onboarding package ข้อความนี้สรุปจากเกณฑ์ที่ผู้ใช้ให้มา ไม่ใช่เอกสารสาธารณะฉบับควบคุม สมาชิกควรใช้ Criteria ล่าสุดที่ได้รับจาก NDID เป็นหลัก

What members prepare for a security assessment

  • Test the member applications, web systems, network layer, and operating systems involved in the NDID Platform connection. The NDID Node is excluded unless the issued criteria state otherwise.
  • The onboarding criteria supplied by the user call for an external juristic-person testing provider and evidence of tester qualifications such as GPEN, eCPPT, OSCP, or another certification accepted by NDID for the member role.
  • Testing follows OSSTMM or NIST SP 800-115 with the OWASP Web/Mobile Testing Guide, or PTES/ISSAF, according to the criteria issued to the member.
  • Critical, High, and Medium findings must be corrected. Low findings are corrected or supported by a recorded rationale, and corrected vulnerabilities are retested.
  • The member submits the final Penetration Test Report and tester certificate to NDID. The supplied criteria state at least annually and after significant changes.
Confirm the current criteria

Details may differ by member role and onboarding package. This summary reflects the criteria supplied by the user, not a publicly controlled document. Members should follow the latest criteria received from NDID.

BANK OF THAILAND / ELECTRONIC MONEY

Bank of Thailand: e-Money and Security Testing

SorNorChor. 7/2561 establishes rules for electronic-money service operators under the Payment Systems Act.

ความเกี่ยวข้องกับ Penetration Testing

  • ใช้กับผู้ประกอบธุรกิจ e-Money ที่ได้รับอนุญาตหรือขึ้นทะเบียนตามกฎหมายว่าด้วยระบบการชำระเงิน
  • ข้อ 4.2.6-4.2.10 เน้นวงเงิน การลงทะเบียนและรับแจ้งสูญหาย การคืนเงิน การตรวจสอบยอดคงเหลือและวันหมดอายุ และการควบคุมการโอนเงินผ่านระบบของผู้ให้บริการ
  • สนช. 7/2561 ไม่ได้กำหนดรอบ Penetration Testing โดยตรง แต่ Flow เหล่านี้ควรถูกนำไปสร้าง Business Logic และ Abuse Case สำหรับการทดสอบ e-Money
  • ข้อกำหนด VA/Penetration Testing โดยตรงสำหรับผู้ประกอบธุรกิจที่อยู่ในขอบเขตมาจากหลักเกณฑ์ IT Risk/Cyber Hygiene ที่ใช้ร่วมกัน เช่น สนช. 1/2564
กำหนด Scope ให้ถูกฉบับ

การถือ e-Money license ไม่ได้ทำให้ทุกข้อใน สนช. 1/2564 ใช้เหมือนกันทั้งหมด ต้องยืนยันประเภทใบอนุญาต ความมีนัยสำคัญ และประกาศฉบับปัจจุบันกับ Compliance ก่อนทดสอบ

เปิดหลักเกณฑ์ e-Money ของ ธปท.

How it relates to Penetration Testing

  • It applies to authorized or registered e-Money operators under the Payment Systems Act.
  • Clauses 4.2.6-4.2.10 address limits, registration and loss reporting, refunds, balance and expiry checks, and control of transfers through the provider's system.
  • SorNorChor. 7/2561 does not directly prescribe a Penetration Testing schedule. These flows should instead inform e-Money business-logic and abuse-case testing.
  • Direct VA/Penetration Testing obligations for in-scope operators arise from applicable IT Risk and Cyber Hygiene rules, such as SorNorChor. 1/2564.
Map the correct rules to scope

Holding an e-Money license does not make every provision of SorNorChor. 1/2564 apply identically. Confirm license type, significance, and the current notifications with Compliance before testing.

Open BOT e-Money regulations

BANK OF THAILAND / CYBER HYGIENE

Bank of Thailand: VA and Penetration Testing - SorNorChor. 1/2564

Direct Cyber Hygiene requirements for Vulnerability Assessment and Penetration Testing by payment-system providers and operators within the notification's scope.

Vulnerability Assessment

  • ข้อ 5.1.6 กำหนดให้ประเมินช่องโหว่ทุกระบบตามระดับความเสี่ยงอย่างน้อยปีละ 1 ครั้ง และเมื่อมีการเปลี่ยนแปลงอย่างมีนัยสำคัญ

Penetration Testing

  • ต้องดำเนินการโดยผู้เชี่ยวชาญที่มีความเป็นอิสระ ครอบคลุมระบบงานและระบบเครือข่ายที่เชื่อมต่อเครือข่ายสาธารณะ อย่างน้อยปีละ 1 ครั้ง และทุกครั้งที่มีการเปลี่ยนแปลงอย่างมีนัยสำคัญ
ขอบเขตการใช้บังคับ

ประกาศใช้กับผู้ให้บริการระบบการชำระเงินที่มีความสำคัญ ผู้ประกอบธุรกิจระบบการชำระเงินภายใต้การกำกับ และผู้ประกอบธุรกิจบริการการชำระเงินภายใต้การกำกับที่มิใช่สถาบันการเงินหรือสถาบันการเงินเฉพาะกิจ ควรยืนยันประเภทใบอนุญาตและประกาศที่มีผลใช้ล่าสุดกับ Compliance

เปิดประกาศ สนช. 1/2564

Vulnerability Assessment

  • Clause 5.1.6 requires vulnerability assessments for all systems according to risk at least annually and after significant changes.

Penetration Testing

  • Independent experts must conduct Penetration Testing of Internet-facing applications and networks at least annually and after every significant change.
Applicability

The notification applies to designated payment-system providers and regulated payment-system or payment-service businesses that are not financial institutions or specialized financial institutions. Confirm the entity's licence and the latest applicable notifications with Compliance.

Open SorNorChor. 1/2564

BANK OF THAILAND / MOBILE BANKING

Bank of Thailand: Mobile Banking Security - Circular 1218/2568 / Notification 4/2568

Minimum Mobile Banking measures used as a testing control baseline, with the Biometric Technology guideline as supplemental guidance where biometrics are used.

1. ขอบเขตของประกาศ

  • ธปท.ว.1218/2568 / ประกาศ ธปท. ที่ 4/2568 ใช้กับสถาบันการเงินทุกแห่งที่ให้บริการ Mobile Banking ตามนิยามในประกาศ

2. Mobile Penetration Testing baseline

  • ขอบเขตทดสอบควรครอบคลุม secure protocol และ certificate pinning, anti-tampering, session security, source code obfuscation, rooted/jailbroken device handling และความเสี่ยงจาก remote-control software หรือ malware
  • ทดสอบทั้ง Mobile Application, API/backend, authentication, transaction flow และ fraud/business logic ที่เชื่อมโยงกัน

3. Biometric Technology เป็นแนวปฏิบัติเสริม

  • หากใช้ชีวมิติ ควรตรวจ Trusted Source, Presentation Attack Detection หรือ liveness, การคุ้มครองข้อมูลชีวมิติ และการบริหารความเสี่ยงตลอดวงจร
รอบการทดสอบ

ประกาศ Mobile Banking และแนวปฏิบัติ Biometric เป็น control baseline แต่ไม่ได้กำหนดรอบ Penetration Testing โดยตนเอง ต้องใช้ร่วมกับข้อกำหนด IT Risk ที่ใช้กับองค์กร

1. Notification scope

  • BOT Circular 1218/2568 / Notification 4/2568 applies to all financial institutions providing Mobile Banking as defined by the notification.

2. Mobile Penetration Testing baseline

  • Testing should assess secure protocols and certificate pinning, anti-tampering, session security, source-code obfuscation, rooted or jailbroken device handling, and risks from remote-control software or malware.
  • Assess the connected mobile application, API/backend, authentication, transaction flows, and fraud or business-logic controls together.

3. Biometric Technology as supplemental guidance

  • Where biometrics are used, assess trusted sources, presentation-attack detection or liveness, biometric-data protection, and lifecycle risk management.
Testing cadence

The Mobile Banking notification and Biometric guideline provide a control baseline; they do not independently prescribe a Penetration Testing cadence. Apply the IT Risk requirements governing the organization.

BANK OF THAILAND / INTELLIGENCE-LED TESTING

Bank of Thailand: iPentest - Circular 1252/2562

The 2019 Intelligence-led Penetration Testing (iPentest) circular addressed commercial banks and assesses readiness to protect against, detect, and respond to cyber threats.

1. Governance และผู้ทดสอบ

  • กำหนดการกำกับดูแลโดยหน่วยงานที่เกี่ยวข้อง รวมถึง IT Risk Management และ Compliance พร้อมผู้รับผิดชอบและเกณฑ์คัดเลือกผู้ทดสอบที่ชัดเจน

2. Threat-informed scope

  • ใช้ Threat Intelligence สร้างสถานการณ์จำลอง และกำหนดขอบเขตให้ครอบคลุม critical functions บุคลากร และกระบวนการป้องกัน ตรวจจับ และรับมือ

3. การควบคุมความเสี่ยง

  • เน้นการทดสอบบน Production เพื่อสะท้อนสถานการณ์จริง แต่ขั้นตอนที่เสี่ยงสามารถย้ายไป UAT หรือ Pre-production และต้องระบุในรายงาน
  • รักษาขอบเขตและเวลาเป็นความลับ กำหนดมาตรการควบคุมความเสี่ยงและช่องทางสื่อสาร แล้วนำผลไปวางแผนแก้ไข
ขอบเขตการใช้บังคับ

หนังสือเวียนปี 2562 ส่งถึงธนาคารพาณิชย์ โดยกำหนดให้ D-SIBs และธนาคารพาณิชย์ที่มี Cyber Inherent Risk ระดับสูงดำเนินการตามแนวปฏิบัติภายในปี 2563 ส่วนธนาคารพาณิชย์อื่นให้พิจารณาตามความเสี่ยงและความพร้อม ไม่ใช่ข้อกำหนดรายปีสำหรับทุกสถาบันการเงิน

เปิดแนวปฏิบัติ iPentest ของธนาคารแห่งประเทศไทย

1. Governance and testers

  • Establish oversight involving relevant functions, including IT Risk Management and Compliance, with clear owners and tester-selection criteria.

2. Threat-informed scope

  • Use threat intelligence to build realistic scenarios and scope critical functions, people, and the processes used to protect, detect, and respond.

3. Risk controls

  • Prefer production testing for realism, while high-risk steps may move to UAT or pre-production and must be identified in the report.
  • Keep scope and timing confidential, define test-risk controls and communications, and use results for remediation planning.
Applicability

The 2019 circular was addressed to commercial banks. It directed D-SIBs and commercial banks with high Cyber Inherent Risk to implement the guideline by 2020, while other commercial banks considered their risk and readiness. It is not a universal annual requirement for every financial institution.

Open the Bank of Thailand iPentest guideline

SEC / DIGITAL ASSET BUSINESS

Penetration Testing Requirements for Digital Asset Businesses

Thai SEC requirements for licensed digital-asset businesses, not requirements issued by the Stock Exchange of Thailand.

ข้อกำหนดโดยตรงสำหรับระบบงานสำคัญ

  • ครอบคลุมผู้ประกอบธุรกิจสินทรัพย์ดิจิทัลตามประเภทใบอนุญาตที่เกี่ยวข้อง เช่น Exchange, Broker, Dealer, Advisory Service และ Fund Manager
  • ข้อ 18 กำหนดให้ทดสอบเจาะระบบงานสำคัญก่อนเริ่มให้บริการ และหลังเริ่มให้บริการอย่างน้อยปีละ 1 ครั้ง โดยบุคคลที่เป็นอิสระจากหน่วยงาน IT ที่รับผิดชอบระบบ
  • ต้องรายงานผลต่อสำนักงาน ก.ล.ต. ภายใน 30 วันนับจากวันที่ได้รับผลอย่างเป็นทางการ และไม่เกิน 90 วันนับจากวันที่สิ้นสุดกระบวนการทดสอบ
  • Scope ต้องเชื่อมกับระบบงานสำคัญจริงของใบอนุญาต เช่น Trading, Wallet/Custody, Customer Portal, API, Infrastructure และระบบสนับสนุนที่มีผลต่อบริการ
หน่วยงานที่ถูกต้องคือ ก.ล.ต.

ธุรกิจสินทรัพย์ดิจิทัลอยู่ภายใต้สำนักงาน ก.ล.ต. ไม่ใช่ SET และรายละเอียดที่ใช้จริงขึ้นกับประเภทใบอนุญาตและประกาศฉบับประมวลล่าสุด

เปิดหลักเกณฑ์ธุรกิจสินทรัพย์ดิจิทัลของ ก.ล.ต.

Direct requirements for critical systems

  • It covers relevant licensed digital-asset business types, including exchanges, brokers, dealers, advisory services, and fund managers.
  • Clause 18 requires Penetration Testing of critical systems before service commencement and at least annually after commencement, performed by a person independent of the IT unit responsible for the systems.
  • Results must be reported to the SEC within 30 days of receiving the official result and no later than 90 days after the testing process ends.
  • Scope should reflect the license's actual critical systems, such as trading, wallet or custody, customer portals, APIs, infrastructure, and supporting systems affecting the service.
The regulator is the SEC

Digital-asset businesses are regulated by the Thai SEC, not the Stock Exchange of Thailand. Applicable details depend on license type and the latest consolidated rules.

Open the SEC digital-asset business rules

NCSA / WEBSITE SECURITY STANDARD

NCSA Website Security Standard B.E. 2568

The Website Security Standard covers governance and security operations across website architectures.

ใครต้องทำและ Penetration Testing เกี่ยวข้องอย่างไร

  • ใช้บังคับกับหน่วยงานของรัฐ หน่วยงานควบคุมหรือกำกับดูแล และหน่วยงานโครงสร้างพื้นฐานสำคัญทางสารสนเทศ (CII) ส่วนเอกชนทั่วไปได้รับการส่งเสริมให้นำไปใช้
  • ประกาศลงวันที่ 16 กันยายน 2568 และมีผลเมื่อพ้นหนึ่งปี จึงมีผลวันที่ 16 กันยายน 2569
  • หน่วยงานในขอบเขตต้องประเมินตนเองตามแบบ ค๑ อย่างน้อยปีละ 1 ครั้ง ประเมินระดับผลกระทบ รายงานตามระดับ และจัดทำแผนแก้ไขแบบ ค๒ เมื่อไม่สอดคล้อง
  • มาตรฐานไม่ได้ทำให้การประเมินตนเองกลายเป็นข้อบังคับ Penetration Testing รายปีโดยอัตโนมัติ แต่ Penetration Testing เป็นหลักฐานเชิงเทคนิคเพื่อพิสูจน์ Website Security Operation และช่องโหว่ที่โจมตีได้จริง
เลือก Scope จาก Impact

Scope ควรครอบคลุม Web Application, Web Server, Database และ Cloud หรือ Web Hosting ที่เกี่ยวข้อง ตามสถาปัตยกรรมและระดับผลกระทบของเว็บไซต์ ไม่ใช่ตรวจเฉพาะหน้าเว็บ

เปิดมาตรฐานเว็บไซต์จากราชกิจจานุเบกษา

Who is in scope and how Penetration Testing supports it

  • It applies to government agencies, regulatory or supervisory bodies, and Critical Information Infrastructure organizations. General private-sector adoption is encouraged.
  • The notification was issued on 16 September 2025 and takes effect after one year, on 16 September 2026.
  • In-scope organizations perform the Kor 1 self-assessment at least annually, determine impact level, report accordingly, and create a Kor 2 remediation plan for gaps.
  • The standard does not automatically turn the annual self-assessment into a blanket annual Penetration Testing requirement. Penetration Testing provides technical evidence for Website Security Operation and exploitable-vulnerability validation.
Derive scope from impact

Scope should cover the web application, web server, database, and relevant cloud or web-hosting components according to the architecture and website impact level, rather than testing only the public pages.

Open the Website Security Standard in the Royal Gazette

OFFICE OF INSURANCE COMMISSION / IT RISK

Office of Insurance Commission (OIC)

IT Risk B.E. 2563 (2020) establishes information technology risk governance and management criteria for life and non-life insurance companies.

Risk-based evidence ไม่ใช่ข้อบังคับ Pentest แบบตายตัว

  • ใช้กับบริษัทประกันภัยที่อยู่ภายใต้การกำกับของสำนักงาน คปภ. เพื่อให้มี Governance, Information Asset Management, IT Risk Management และ Cybersecurity controls ที่เหมาะสม
  • ประกาศหลักไม่ได้กำหนดรูปแบบหรือความถี่ของ Penetration Testing โดยตรง และไม่ได้บังคับว่าจะต้องเป็น Black-box, Grey-box หรือ White-box
  • Penetration Testing สามารถใช้เป็นหลักฐานเชิงเทคนิคเพื่อประเมินประสิทธิผลของมาตรการควบคุมและความเสี่ยงที่โจมตีได้จริง โดยเลือก Scope จาก Information Asset Inventory และผล Risk Assessment
  • ระบบที่ควรพิจารณาตามความเสี่ยง ได้แก่ Core Insurance Systems, Customer/Agent Portals, Mobile Applications, APIs, External-facing systems และ Infrastructure ที่จัดเก็บข้อมูลสำคัญ
ประโยชน์ต่อการบริหารความเสี่ยง

Penetration Testing ช่วยให้องค์กรมีหลักฐานที่ตรวจสอบได้สำหรับการบริหารความเสี่ยงด้านเทคโนโลยีสารสนเทศ และประเมินประสิทธิผลของมาตรการควบคุม โดยขอบเขตและรอบการทดสอบควรกำหนดตามความเสี่ยงของระบบและข้อกำหนดที่ใช้กับองค์กรของคุณ

Risk-based evidence, not a fixed Penetration Testing mandate

  • It applies to insurance companies supervised by the Office of Insurance Commission and establishes expectations for governance, information-asset management, IT risk management, and cybersecurity controls.
  • The principal notification does not directly prescribe a Penetration Testing method or frequency, nor does it mandate black-box, grey-box, or white-box testing.
  • Penetration Testing can provide technical evidence of control effectiveness and exploitable risk, with scope derived from the information-asset inventory and risk assessment.
  • Risk-based candidates include core insurance systems, customer and agent portals, mobile applications, APIs, external-facing systems, and infrastructure holding sensitive data.
Accurate customer wording

State that Penetration Testing supports IT Risk management and control validation. Do not claim the OIC mandates annual Penetration Testing unless another requirement applicable to that insurer does so.

OFFICIAL CREST REGISTRY

Verify CREST Pathway Plus

Learn who CREST is, what Pathway+ status means, and how it supports confidence when choosing STH as a penetration testing provider.

CREST Pathway Plus
Pathway+ registered organisation Siam Thanat Hack

CREST is an international not-for-profit membership body that sets and raises standards for Cyber Security providers and professionals, giving buyers, governments, and regulators greater confidence in the industry.

CREST Pathway+ recognises organisations that have progressed beyond the initial Pathway stage and completed an assessment against CREST company requirements in the Security Assessment discipline, which includes Penetration Testing and Vulnerability Assessment. The assessment helps measure readiness and identify opportunities to strengthen quality.

STH's Pathway+ status and listing in the official CREST registry show a structured quality-improvement journey, alignment with CREST's Code of Conduct, and a commitment to strengthening governance, delivery methods, and information protection against internationally recognised standards. This gives clients a more transparent reference point when evaluating a penetration testing provider.

Open the CREST registry at Siam Thanat Hack

STH BRAND ASSETS

Download STH logos

Choose the version that fits your background and download the original PNG.

PROJECT INTAKE

Request a pentest quote

Share your systems, required services, and preferred timeframe so the STH team can assess the project and contact you.

01

Contact details

02 Services

03

Project Scope

04

Preferred service date

CERTIFICATE / PDF PREVIEW

ISO/IEC 27001:2022

Siam Thanat Hack Information Security Management System certificate

CERTIFICATE / PDF PREVIEW

ISO 9001:2015

Siam Thanat Hack Quality Management System certificate

COMPANY CERTIFICATE / PDF PREVIEW

Company certificate

Siam Thanat Hack company registration certificates in Thai and English

VAT REGISTRATION / PDF PREVIEW

VAT registration (PP.20)

VAT registration copies for the head office and Branch 1

SME-GP / PDF PREVIEW

SME-GP registration

SME registration certificate for government procurement

CERTIFICATE / PDF PREVIEW

Consultant registration

Consultant registration certificate from the Ministry of Finance Consultant Database Center

AWARD / PDF PREVIEW

Prime Minister Awards 2024

Thailand Cybersecurity Excellence Award 2024 - Contribution Award

AWARD / PDF PREVIEW

Prime Minister Awards 2025

Thailand Cybersecurity Excellence Awards 2025 - Best Performance Awards